Chord-and-tangent addition on a real curve, rolled up into the finite-field torus.
Over the real numbers, the line through two points P and Q of y^2 = x^3 + ax + b meets the cubic exactly once more, and reflecting that point in the x axis defines P + Q. The same slope formulas work modulo a prime when division means a modular inverse, so the curve becomes a scatter of integer points on a p x p grid whose opposite edges are glued, and the demo rolls that grid into the torus it really is: it squashes, rolls into a tube and bends into a ring, drawn as painter-sorted, lit 3D quads. Repeatedly adding a generator G sends kG hopping chaotically around the surface, and a full elliptic-curve Diffie-Hellman exchange runs on it: Alice and Bob each compute a public point with double-and-add, then both reach the same shared secret abG. Every number shown is computed exactly, including the generator's order and the number of points on the curve.
Try it. Drag P and Q along the real curve (two components when it has three real roots); drag them together for the tangent case. Switch between Reals, Field and Torus with the tabs or keys 1 to 3, change a and b with the steppers or arrow keys and the prime with the stepper or [ and ]. In the field, click two points to add them and see the wrapped line through them. Space adds G once more and K runs a new key exchange.
Paste this into Claude Code, Codex or any coding agent to get a simple version running, then take it wherever you like.
Build an interactive elliptic curve explorer with JavaScript and the HTML canvas element. Put everything in a single index.html file with no libraries or build step, so I can open it directly in a browser.
Start simple:
- Plot y^2 = x^3 + ax + b over the reals with a = -4 and b = 2. Find the real roots of the cubic numerically and sample each piece of the curve densely near the roots, where it turns vertical, so the closed oval and the open branch both draw smoothly.
- Put two points P and Q on the curve that the mouse can drag (snap to the nearest sample). Draw the line through them, the third point where it meets the curve, and its reflection in the x axis, labeled P + Q. Handle the tangent case (P = Q) and the vertical line (the point at infinity).
- Add a second view: the same equation modulo a prime p such as 97. Loop over every x and y, keep the pairs that satisfy the equation mod p, and draw them on a p x p grid.
- Implement the group law mod p with a modular inverse from the extended Euclidean algorithm, pick a generator G, and animate kG for k = 1, 2, 3... with a fading trail.
Once that works, make it beautiful:
- Glow the curve and the points, and give each point role (P, Q, the sum, G) its own color.
- Show that the grid wraps: draw hop trails using the shortest displacement across the edges.
- Run a small Diffie-Hellman key exchange: secret a and b, public aG and bG computed with double-and-add, and the shared point abG that both sides reach.
Explain the key ideas in short code comments. When you're done, tell me how to open it and suggest three directions I could take it next, such as rolling the grid into a 3D torus, drawing the wrapped line through two field points, or counting the points on the curve and comparing with Hasse's bound.